Re: Re: LiveUser password encryption

From: Date: Thu, 10 Jun 2004 21:23:26 +0000
Subject: Re: Re: LiveUser password encryption
References: 1 2  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-13093@lists.php.net to get a copy of this message
I've got the same problem to take care of. Been using PASSWORD() forever with MySQL without realizing that I should have been using either MD5() or SHA(). Now I have to manage a conversion. My thought was (and this is a LITTLE off-topic) was ... 1. Temporarily add a enum(T/F) field to the user table named
     "passwd_converted" (or something to that effect)
2. Before the user logs in, check the value of the "passwd_converted"
     field.
3. If "F" then
        1. User form contains a hidden field "changefunc" to indicate
           that the password needs updating with the value of the new
           function
        2. We know to use PASSWORD() to validate password
4. If "T" then
        1. nothing to change since the password field contains the
           correct password hash.
        2. use the new function to validate password
5. After the user has logged in successfully, if we needed to change
     the password hash then we update the password field and the
     "passwd_converted" field.
6. QED That'll probably be my path. FWIW, my $0.02. If anyone has a better suggestion, I'm open to hearing it. -- matte - matte@arubanetworks.com webmonkey / arubanetworks.com / airheads04.com / wi-fi-it.com Michael Wallner wrote: > mishal@centrum.cz wrote: > >> my question is: is it possible to use liveuser with mysql password >> function? > > > Hi, unfortunately I don't know the internals of > LiveUser, but one thing I can say for sure is, > that using MySQLs PASSWORD() is definitely a > bad thing [tm]. MySQL AB itself states that this function may be > changed without warning. > > You should probably watch out for a way > to change the current system to use a more reliable way of storing > your passwords.

« previous php.pear.general (#13093) next »